๐ต๏ธ RESEARCH & DEEP DIVES
-
Black Hat speakers detail enterprise Java pre-auth RCE and AI-agent hijacking
Black Hat speakers discussed enterprise Java pre-auth RCE and AI coding-agent hijacking.- Enterprise Java deployments and AI coding agents are affected.
- The discussion covered pre-auth remote code execution in enterprise Java.
- AI coding agents can be hijacked.
๐ Source: cursor.com ยท ๐ Coverage: pwnhackers.substack.com ยท ๐ via r/netsec
-
Authenticated command injection found in Zyxel export-cgi PKCS#12 handling
CVE-2026-6837
An authenticated command-injection flaw affects Zyxel's export-cgi PKCS#12 certificate export flow.- Zyxel products using the export-cgi certificate export functionality are affected.
- CVE-2026-6837 enables command injection during PKCS#12 certificate export handling.
- An authenticated attacker can submit crafted export input to execute commands on the device.
- Affected firmware versions were not specified in the available material.
๐ Source: minanagehsalalma.github.io ยท ๐ Coverage: reddit.com ยท ๐ via r/netsec